poppler: SIGABRT PDFDoc::setup class in PDFDoc.cc
Published Jan 3, 2019
6.5
MEDIUMCVSS 3.1
EPSS 2.26%
Description
In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in which an xref data structure is mishandled during extractPDFSubtype processing.
Affected products
No data.
Configuration 1
- 0.72.0
Configuration 2
- 8.0
- 9.0
Configuration 3
- 28
- 29
- 30
Configuration 4
- 16.04
- 18.04
- 18.10
- 19.04
Configuration 5
- 8.0
- 7.0
- 8.1
- 8.2
- 8.4
- 8.6
- 7.0
- 8.2
- 8.4
- 8.6
- 8.2
- 8.4
- 8.6
- 7.0
No data.
Red Hat Enterprise Linux 7
evince-0:3.28.2-8.el7
Fixed · RHSA-2019:2022
Red Hat Enterprise Linux 7
okular-0:4.10.5-7.el7
Fixed · RHSA-2019:2022
Red Hat Enterprise Linux 7
poppler-0:0.26.5-38.el7
Fixed · RHSA-2019:2022
Red Hat Enterprise Linux 8
poppler-0:0.66.0-11.el8_0.12
Fixed · RHSA-2019:2713
Red Hat Enterprise Linux 5
poppler
Will not fix
Red Hat Enterprise Linux 6
poppler
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | evince-0:3.28.2-8.el7 | Fixed | RHSA-2019:2022 |
| Red Hat Enterprise Linux 7 | okular-0:4.10.5-7.el7 | Fixed | RHSA-2019:2022 |
| Red Hat Enterprise Linux 7 | poppler-0:0.26.5-38.el7 | Fixed | RHSA-2019:2022 |
| Red Hat Enterprise Linux 8 | poppler-0:0.66.0-11.el8_0.12 | Fixed | RHSA-2019:2713 |
| Red Hat Enterprise Linux 5 | poppler | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | poppler | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (15)
- https://access.redhat.com/errata/RHSA-2019:2022 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2713 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-20662 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1665273 Issue Tracking
- https://gitlab.freedesktop.org/poppler/poppler/commit/9fd5ec0e6e5f763b190f2a55ceb5427cfe851d5f x_refsource_MISCPatchThird Party Advisory
- https://gitlab.freedesktop.org/poppler/poppler/issues/706 x_refsource_MISCThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/03/msg00008.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/11/msg00014.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6OSCOYM3AMFFBJWSBWY6VJVLNE5JD7YS/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BI7NLDN2HUEU4ZW3D7XPHOAEGT2CKDRO/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JQ6RABASMSIMMWMDZTP6ZWUWZPTBSVB5/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZWP5XSUG6GNRI75NYKF53KIB2CZY6QQ6/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2018-20662
- https://usn.ubuntu.com/4042-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-20662
Change history (0)
No recorded changes yet.